<!-- 
RSS generated by JIRA (9.4.14#940014-sha1:734e6822bbf0d45eff9af51f82432957f73aa32c) at Sat Feb 10 03:25:32 UTC 2024

It is possible to restrict the fields that are returned in this document by specifying the 'field' parameter in your request.
For example, to request only the issue key and summary append 'field=key&field=summary' to the URL of your request.
-->
<rss version="0.92" >
<channel>
    <title>Whamcloud Community JIRA</title>
    <link>https://jira.whamcloud.com</link>
    <description>This file is an XML representation of an issue</description>
    <language>en-us</language>    <build-info>
        <version>9.4.14</version>
        <build-number>940014</build-number>
        <build-date>05-12-2023</build-date>
    </build-info>


<item>
            <title>[LU-16273] kernel update [SLES15 SP3 5.3.18-150300.59.98.1]</title>
                <link>https://jira.whamcloud.com/browse/LU-16273</link>
                <project id="10000" key="LU">Lustre</project>
                    <description>&lt;p&gt;   The SUSE Linux Enterprise 15 SP3 kernel was updated.&lt;/p&gt;

&lt;p&gt;   The following security bugs were fixed:&lt;/p&gt;

&lt;ul class=&quot;alternate&quot; type=&quot;square&quot;&gt;
	&lt;li&gt;CVE-2022-40768: Fixed information leak in the scsi driver which allowed&lt;br/&gt;
     local users to obtain sensitive information from kernel memory.&lt;br/&gt;
     (bnc#1203514)&lt;/li&gt;
	&lt;li&gt;CVE-2022-3169: Fixed a denial of service flaw which occurs when&lt;br/&gt;
     consecutive requests to NVME_IOCTL_RESET and the NVME_IOCTL_SUBSYS_RESET&lt;br/&gt;
     are sent. (bnc#1203290)&lt;/li&gt;
	&lt;li&gt;CVE-2022-42722: Fixed crash in beacon protection for P2P-device.&lt;br/&gt;
     (bsc#1204125)&lt;/li&gt;
	&lt;li&gt;CVE-2022-42719: Fixed MBSSID parsing use-after-free. (bsc#1204051)&lt;/li&gt;
	&lt;li&gt;CVE-2022-42721: Avoid nontransmitted BSS list corruption. (bsc#1204060)&lt;/li&gt;
	&lt;li&gt;CVE-2022-42720: Fixed BSS refcounting bugs. (bsc#1204059)&lt;/li&gt;
	&lt;li&gt;CVE-2022-3303: Fixed a race condition in the sound subsystem due to&lt;br/&gt;
     improper locking (bnc#1203769).&lt;/li&gt;
	&lt;li&gt;CVE-2022-41218: Fixed an use-after-free caused by refcount races in&lt;br/&gt;
     drivers/media/dvb-core/dmxdev.c (bnc#1202960).&lt;/li&gt;
	&lt;li&gt;CVE-2022-3239: Fixed an use-after-free in the video4linux driver that&lt;br/&gt;
     could lead a local user to able to crash the system or escalate their&lt;br/&gt;
     privileges (bnc#1203552).&lt;/li&gt;
	&lt;li&gt;CVE-2022-41848: Fixed a race condition and resultant use-after-free if a&lt;br/&gt;
     physically proximate attacker removes a PCMCIA device while calling&lt;br/&gt;
     ioctl (bnc#1203987).&lt;/li&gt;
	&lt;li&gt;CVE-2022-41849: Fixed a race condition and resultant use-after-free if a&lt;br/&gt;
     physically proximate attacker removes a USB device while calling open&lt;br/&gt;
     (bnc#1203992).&lt;/li&gt;
	&lt;li&gt;CVE-2022-41674: Fixed a DoS issue where kernel can crash on the&lt;br/&gt;
     reception of specific WiFi Frames (bsc#1203770).&lt;/li&gt;
	&lt;li&gt;CVE-2022-2586: Fixed a use-after-free which can be triggered when a nft&lt;br/&gt;
     table is deleted (bnc#1202095).&lt;/li&gt;
	&lt;li&gt;CVE-2022-41222: Fixed a use-after-free via a stale TLB because an rmap&lt;br/&gt;
     lock is not held during a PUD move (bnc#1203622).&lt;/li&gt;
	&lt;li&gt;CVE-2022-2503: Fixed a bug in dm-verity, device-mapper table reloads&lt;br/&gt;
     allowed users with root privileges to switch out the target with an&lt;br/&gt;
     equivalent dm-linear target and bypass verification till reboot. This&lt;br/&gt;
     allowed root to bypass LoadPin and can be used to load untrusted and&lt;br/&gt;
     unverified kernel modules and firmware, which implies arbitrary kernel&lt;br/&gt;
     execution and persistence for peripherals that do not verify firmware&lt;br/&gt;
     updates (bnc#1202677).&lt;/li&gt;
	&lt;li&gt;CVE-2022-20008: Fixed a bug which allowed to read kernel heap memory due&lt;br/&gt;
     to uninitialized data. This could lead to local information disclosure&lt;br/&gt;
     if reading from an SD card that triggers errors, with no additional&lt;br/&gt;
     execution privileges needed. (bnc#1199564)&lt;/li&gt;
	&lt;li&gt;CVE-2020-16119: Fixed a use-after-free vulnerability exploitable by a&lt;br/&gt;
     local attacker due to reuse of a DCCP socket. (bnc#1177471)&lt;/li&gt;
&lt;/ul&gt;


&lt;p&gt;   The following non-security bugs were fixed:&lt;br/&gt;
   &lt;a href=&quot;https://lists.suse.com/pipermail/sle-security-updates/2022-October/012711.html&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://lists.suse.com/pipermail/sle-security-updates/2022-October/012711.html&lt;/a&gt;&lt;/p&gt;</description>
                <environment></environment>
        <key id="72965">LU-16273</key>
            <summary>kernel update [SLES15 SP3 5.3.18-150300.59.98.1]</summary>
                <type id="4" iconUrl="https://jira.whamcloud.com/secure/viewavatar?size=xsmall&amp;avatarId=11310&amp;avatarType=issuetype">Improvement</type>
                                            <priority id="4" iconUrl="https://jira.whamcloud.com/images/icons/priorities/minor.svg">Minor</priority>
                        <status id="5" iconUrl="https://jira.whamcloud.com/images/icons/statuses/resolved.png" description="A resolution has been taken, and it is awaiting verification by reporter. From here issues are either reopened, or are closed.">Resolved</status>
                    <statusCategory id="3" key="done" colorName="success"/>
                                    <resolution id="2">Won&apos;t Fix</resolution>
                                        <assignee username="yujian">Jian Yu</assignee>
                                    <reporter username="yujian">Jian Yu</reporter>
                        <labels>
                    </labels>
                <created>Thu, 27 Oct 2022 17:52:06 +0000</created>
                <updated>Fri, 18 Nov 2022 20:23:13 +0000</updated>
                            <resolved>Fri, 18 Nov 2022 20:23:13 +0000</resolved>
                                                                        <due></due>
                            <votes>0</votes>
                                    <watches>2</watches>
                                                                            <comments>
                            <comment id="351010" author="gerrit" created="Thu, 27 Oct 2022 17:58:12 +0000"  >&lt;p&gt;&quot;Jian Yu &amp;lt;yujian@whamcloud.com&amp;gt;&quot; uploaded a new patch: &lt;a href=&quot;https://review.whamcloud.com/c/fs/lustre-release/+/48974&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://review.whamcloud.com/c/fs/lustre-release/+/48974&lt;/a&gt;&lt;br/&gt;
Subject: &lt;a href=&quot;https://jira.whamcloud.com/browse/LU-16273&quot; title=&quot;kernel update [SLES15 SP3 5.3.18-150300.59.98.1]&quot; class=&quot;issue-link&quot; data-issue-key=&quot;LU-16273&quot;&gt;&lt;del&gt;LU-16273&lt;/del&gt;&lt;/a&gt; kernel: kernel update SLES15 SP3 &lt;span class=&quot;error&quot;&gt;&amp;#91;5.3.18-150300.59.98.1&amp;#93;&lt;/span&gt;&lt;br/&gt;
Project: fs/lustre-release&lt;br/&gt;
Branch: master&lt;br/&gt;
Current Patch Set: 1&lt;br/&gt;
Commit: 7846cd6011d893399715578e28452757d2ff41a9&lt;/p&gt;</comment>
                            <comment id="353576" author="yujian" created="Fri, 18 Nov 2022 20:23:13 +0000"  >&lt;p&gt;A new version is available in &lt;a href=&quot;https://jira.whamcloud.com/browse/LU-16325&quot; title=&quot;kernel update [SLES15 SP3 5.3.18-150300.59.101.1]&quot; class=&quot;issue-link&quot; data-issue-key=&quot;LU-16325&quot;&gt;&lt;del&gt;LU-16325&lt;/del&gt;&lt;/a&gt;.&lt;/p&gt;</comment>
                    </comments>
                <issuelinks>
                            <issuelinktype id="10011">
                    <name>Related</name>
                                            <outwardlinks description="is related to ">
                                        <issuelink>
            <issuekey id="72432">LU-16173</issuekey>
        </issuelink>
                            </outwardlinks>
                                                                <inwardlinks description="is related to">
                                        <issuelink>
            <issuekey id="73327">LU-16325</issuekey>
        </issuelink>
                            </inwardlinks>
                                    </issuelinktype>
                    </issuelinks>
                <attachments>
                    </attachments>
                <subtasks>
                    </subtasks>
                <customfields>
                                                                                                                                                                                            <customfield id="customfield_10890" key="com.atlassian.jira.plugins.jira-development-integration-plugin:devsummary">
                        <customfieldname>Development</customfieldname>
                        <customfieldvalues>
                            
                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                        <customfield id="customfield_10390" key="com.pyxis.greenhopper.jira:gh-lexo-rank">
                        <customfieldname>Rank</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>1|i033wn:</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                <customfield id="customfield_10090" key="com.pyxis.greenhopper.jira:gh-global-rank">
                        <customfieldname>Rank (Obsolete)</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>9223372036854775807</customfieldvalue>
                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                                                                                </customfields>
    </item>
</channel>
</rss>